OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • Archive »
  • 19.1 Legacy Series »
  • OPNSense behind ISP Modem; all traffic blocked
« previous next »
  • Print
Pages: [1]

Author Topic: OPNSense behind ISP Modem; all traffic blocked  (Read 4448 times)

malchir

  • Newbie
  • *
  • Posts: 2
  • Karma: 0
    • View Profile
OPNSense behind ISP Modem; all traffic blocked
« on: April 22, 2019, 07:57:45 pm »
Hello all,

I have the following setup:

Internet -- ISP modem -- OPNSense -- l3 switch

ISP modem - OPNSense subnet : 192.168.178.0/24 (.1 <-> .252)
OPNSense -- L3 Switch 10.34.10.0/24
L3 Switch - 10.34.0.0/16 (several VLANs).

I've added FW rules to allow 10.34.0.0/16 (added routing and gateway too) to any but traffic gets blocked by "Default Rule". I've made it more specific by adding /24 subnet rules but traffic stays blocked. I've searched through OPNSense and PFSense posts but I cannot get a right answer why something pretty obvious gets blocked. Am I missing NAT rules (it's double NAT, yeah not perfect but it works)? I've disabled blocking RFC1918 en bogon networks.

At the moment I use an ASA 5505 and that works but as soon as I switch the default route to the OPNSense FW (on the L3 switch) the logs fill up with block spam.

I must be overlooking something but I do not see it at the moment.

With kind regards,

Marcel Tempelman.

 
Logged

bartjsmit

  • Hero Member
  • *****
  • Posts: 2023
  • Karma: 194
    • View Profile
Re: OPNSense behind ISP Modem; all traffic blocked
« Reply #1 on: April 22, 2019, 08:59:48 pm »
Are you allowing RFC 1918 on your WAN interface? Interfaces, WAN, make sure 'Block private networks' is unticked.

Bart...
Logged

Maurice

  • Hero Member
  • *****
  • Posts: 1213
  • Karma: 158
    • View Profile
    • GitHub
Re: OPNSense behind ISP Modem; all traffic blocked
« Reply #2 on: April 22, 2019, 09:26:53 pm »
If you want OPNsense to perform NAT for subnets other than those of its LAN interfaces, you need to add manual outbound NAT rules.
« Last Edit: April 23, 2019, 01:03:55 am by Maurice »
Logged
OPNsense virtual machine images
OPNsense aarch64 firmware repository

Commercial support & engineering available. PM for details (en / de).

malchir

  • Newbie
  • *
  • Posts: 2
  • Karma: 0
    • View Profile
Re: OPNSense behind ISP Modem; all traffic blocked
« Reply #3 on: April 23, 2019, 07:26:40 pm »
Thx Maurice ! That was what fixed it. I was still using the automatic setting. Just added a NAT rule for my 10.34.0.0/16 subnet and it worked !

with kind regards,

Marcel Tempelman
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • Archive »
  • 19.1 Legacy Series »
  • OPNSense behind ISP Modem; all traffic blocked
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2